GDPR Privacy Principles: Lawful, Fair and Transparent

Article 5(1)a of the GDPR is simple. It sets out the first of the GDPR privacy principles: “personal data shall be processed in a lawful, fair and transparent manner in relation to the data subject”.

These means the GDPR requires organisations to process personal data lawfully, fairly, and transparently.

These are three separate but closely connected requirements.

The principle applies to all processing of personal data and underpins a range of other GDPR requirements.

Before an organisation considers data minimisation, retention periods, security controls, or accountability, it must first be able to answer three questions:

  • Do we have a lawful reason for processing this information?
  • Are we treating people fairly?
  • Are we being open and honest about what we are doing?

 

Fairness

 

What Does Lawfulness, Fair and Transparent Mean?

Lawful Processing

To process personal data lawfully under GDPR, organisations must have a lawful basis for doing so. There are seven main lawful bases set out in the GDPR (a seventh having been recently added by the 2025 Data Use and Access Act). They are:

  • Consent: Individuals willingly agree to their data being processed.
  • Contractual Obligations: Data processing is required to fulfill a contract.
  • Legal Obligations: Processing is necessary to comply with legal obligations.
  • Vital Interests: Data processing is vital to protect someone’s life.
  • Public Authority: Processing is performed as an official function or task.
  • Legitimate Interests: Organisations have an identified legitimate interest in processing personal data, but it must not override individuals’ rights, sand must take steps to balance privacy with their data processing aims.
  • Recognised legitimate interests: some things such as safeguarding are automatically considered to be legitimate uses of data and as such a balancing test is not needed.

Determining with lawful basis applies depends on the purpose you want the data for.

Special Category Data

Certain types of personal data get additional protections under the GDPR. These are known as special category data and include information such as:

  • health related data
  • information related to ethnicity
  • religious, social or cultural beliefs
  • criminal record data

Because these categories of data have special protection a further lawful basis is needed to process data of this type.

Fairness

While “lawfulness” asks if you have a legal basis to process data, fairness asks whether you are treating the individual honestly, reasonably, and in a way that respects their reasonable expectations.

In essence, fairness is about ensuring that you are not using personal data in a way that is detrimental, unexpected, or misleading to the individual.

Key Dimensions of Fairness

To determine if processing is fair, organisations must consider:

  • Reasonable Expectations: Data should only be used in ways that a normal person would reasonably expect. If an individual provides their email address to receive a receipt, they would not reasonably expect to be signed up for a third-party marketing list. Using their data for that unexpected purpose is unfair.
  • Avoiding Detriment: Processing must not result in unjustified adverse effects for the individual. This includes discrimination, manipulation, or causing unnecessary distress. If a process unfairly penalises a specific group, even if the processing is technically lawful, it violates the fairness principle.
  • Power Imbalances: Fairness is particularly important where there is a power imbalance, such as between an employer and employee, or a dominant service provider and a consumer. Because the individual has little choice but to agree to the processing, the organisation has an enhanced duty to ensure the terms are not exploitative or unfair.
  • Avoiding Deception (Transparency Link): Fairness and transparency go hand-in-hand. An organisation cannot be fair if it hides how it uses data or uses “dark patterns” (manipulative design) to trick users into giving consent. Fairness requires that you are open, honest, and do not mislead individuals about the consequences of their choices.

Why it Matters

Even if an organisation has a legal basis (like legitimate interests), that basis can be invalidated if the processing itself is fundamentally unfair. It prevents organisations from using data in ways that are technically legal but morally or ethically indefensible.

Key Questions

  • Would individuals reasonably expect this processing?
  • Could the processing cause harm?
  • Is there a significant imbalance of power?
  • Are vulnerable people involved?
  • Are decisions being made responsibly?

Transparency

Organisations must be open and clear about how personal data are collected, used, stored, and shared.

The GDPR sets out that it should be clear to people that personal data concerning them are collected, used, and processed. The principle of transparency requires that any information and communication relating to the processing of those personal data be easily accessible and easy to understand, and that clear and plain language be used.

This links to fairness – if you are collecting and processing data about children or other vulnerable people you will need to consider how they will understand your data processing activities.

Crucially transparency requires that people are informed of this at the time data about them are collected.

Overall individuals should understand:

  • what information is collected
  • why it is collected
  • how it will be used
  • who it will be shared with
  • how long it will be retained
  • what rights they have

 

How Lawfulness, Fairness and Transparency Work Together

Imagine an online retailer collects customer email addresses to keep customers informed of deliveries.

Lawful?

The retailer has a lawful basis for processing this data, because it needs it to fulfil the contract between it and the customer.

Fair?

Using the addresses for unrelated purposes may be unfair. For example, using the emails for marketing purposes needs a separate lawful basis and must be explained in any privacy information. However, it still may not be data processing the customer expects.

Transparent?

If customers were not informed about the use of their emails for marketing purposes, transparency is missing as well as fairness.

The three elements of the first privacy principle should be considered together. A processing activity can fail this principle even if only one element is missing.

Applying the Principle Throughout the Information Lifecycle

Data processing happens throughout the information lifecycle so the first data privacy principles must be considered at each step and for each processing activity.

Data Collection

  • Explain the purposes you need data for clearly, in a way your audience would understand.
  • Identify lawful bases. For example, an online retailer might use the contractual basis to fulfil an order, legitimate interests or consent for marketing, and the statutory duty basis if it needs to check customers are over 18.
  • Make the privacy information easily accessible.

Data Use

  • Use information consistently with stated purposes, and not using it for other things that are not included in your privacy information
  • Avoid unexpected processing by planning carefully for your data needs

Data Sharing

  • Inform individuals when data are shared with other organisations and ensure the sharing is justified.

Data Retention

  • Retain information only in line with retention periods and appropriate policies. If possible set out retention practices in your privacy statement.

Data Disposal

  • Dispose of information securely, using a method appropriate to the sensitivity of the data and the vulnerability of data subjects. This does not need to be set out in your privacy statement, but it still must be fair.

Lawfulness, fairness and transparency should guide every stage of processing.

The Role of Privacy Notices

Privacy notices help organisations explain:

  • who they are
  • why they process personal data
  • lawful bases
  • recipients
  • retention periods
  • individual rights

Good privacy notices should be

  • clear
  • concise
  • accessible
  • easy to understand

Common Mistakes

Writing privacy notices solely for lawyers or regulators rather than for the people whose data are being processed.

One approach many organisations take is to have a more layered privacy notice:

  1. a simple web page setting out at a high level core data processing activities in line with the concept of lawful fair and transparent. An advantage of this is organisations can use videos or animations rather than text.
  2. A more detailed technical statement that goes into more depth for people who need it, perhaps in the form of a downloadable document
  3. The contact details of an organisation’s Data Protection Officer for any outstanding questions people may have.

Common Misconceptions

There are a number of errors organisations make with their privacy information that we have seen

We Have Consent, So Everything Is Fine

Consent is a lawful basis but that alone does not guarantee fairness. People must still have a full understanding of any data processing they are consenting to.

If It Is Legal, It Must Be Fair

Lawfulness and fairness are separate requirements and it does not follow that having a lawful basis for data processing means that processing is fair

People Never Read Privacy Notices

People do. And if people choose not to transparency is still required. If anyone raises a query or concern your privacy and transparency information will be a key tool you can refer to and rely on.

Employees Don’t Need Privacy Notices

Employees are data subjects too and should have privacy information provided to them whether separately or as part of your main transparency efforts.

Using a Generic Privacy Statement Template

A generic template will not cover all of your data processing because different lawful bases can apply to the same processing activity, such as marketing, and because every organisation’s data subjects are different. Every template must be adapted and be specific to your organisation.

  • read more about common privacy statement mistakes here.

Practical Examples

Recruitment

Candidate data is often processed under the contractual lawful basis (your are considering offering a contract of employment) and the statutory duty basis (employers have a legal duty to check if people have the right to work in the UK).

Inform candidates how their information will be used, and how long it will be retained if candidates are unsuccessful. If you use AI to screen candidates or applications you must make this clear in your transparency information.

Employee Management

Personal data will be processed for employment purposes to deliver on employment contracts:

  • Payroll
  • Performance management, appraisal and monitoring
  • Sickness absence management and occupational health

Employee focused privacy information will set out all of these uses and explain what they are for.

Customer Services

Customer data will be processed for a range of reasons. To fulfil a contract (including credit checks, payment and delivery), to market other products and services, and to seek feedback or reviews. Again this would rely on a mix of lawful bases: contractual; legitimate interests; and/or consent.

Provide clear explanations about data use to customers and make it readily available before they purchase anything or make an enquiry. You must ensure that if people do not give consent to activities like marketing you do not include them in your marketing materials.

CCTV

Inform individuals that monitoring is taking place and explain why. This can be done with signage but crucially that signage must be visible at or before the point people enter the area being filmed.

Demonstrating Compliance

Organisations are accountable for demonstrating their compliance with the first privacy principle. Evidence organisations may need to show compliance includes:

  • privacy notices
  • records of processing activities
  • lawful basis assessments
  • legitimate interests assessments
  • DPIAs
  • policies and procedures
  • training records
  • evidence of data destruction

Organisations should be able to demonstrate how they have considered lawfulness, fairness, and transparency as part of their processing activities throughout the information life cycle

Relationship to Other GDPR Privacy Principles

The principle of lawful, fair and transparent is one of several privacy principles and they do not sit in isolation. They interact with each other and support overall compliance. For example:

Purpose Limitation

Knowing what you do and do not process personal data for supports transparency.

Data Minimisation

Limiting the data you collect supports fairness.

Accountability

Requires evidence of compliance.

Lawfulness, fairness and transparency influences all the GDPR privacy principles and it in turn influenced by them.

Practical Checklist

Before processing personal data ask:

  • Do we have a lawful basis?
  • Would individuals reasonably expect this processing?
  • Could the processing cause unfair impacts?
  • Have we explained the processing clearly?
  • Is the information accessible and understandable?
  • Can we demonstrate our reasoning?

Conclusion

As the first data privacy principle lawfulness, fairness and transparency are the foundation of GDPR compliance. Organisations must be able to justify, explain, and defend their processing activities.

Effective compliance with this principle requires more than identifying a lawful basis. You must be reasonable and fair in your data collection and processing. Openness, trust, and responsible decision-making are key.